None
Spire agent should run as a user with only required capabilities enabled for the container.
openshift/openshift-docs#103679: OSDOCS-17626 updated zero-trust release notes for GA
openshift/zero-trust-workload-identity-manager#50: SPIRE-238, SPIRE-60: Restrict SCC for spire-agent